Threat actors targeted cryptocurrency and NFT communities with phishing messages and spoofed NFT project websites that impersonated legitimate services to trick users into downloading malware. One campaign used a fake Pixelmon site, pixelmon[.]pw, to mimic the real project and deliver ZIP archives containing Windows shortcut and script payloads that installed Vidar infostealer, which steals passwords, cryptocurrency wallet data, and sensitive files. Researchers found Vidar obtained command-and-control details through a Telegram channel and could fetch additional modules from its C2 infrastructure.
A separate but related campaign tracked as NFT-001 used Discord and similar forums to lure victims to decoy crypto sites, where a malicious installer deployed Remcos RAT and, in newer variants, Eternity Stealer. Morphisec reported the operators changed tooling from the Babadeda crypter to a staged downloader while keeping similar delivery infrastructure and some overlapping C2 elements. The newer downloader performed a UAC bypass, added C:\ to Microsoft Defender exclusions, and retrieved follow-on payloads to improve evasion and credential theft, showing continued refinement of malware delivery against NFT and crypto users.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
In June 2022, the NFT-001 threat actor changed its delivery chain from the Babadeda crypter to a new staged downloader while keeping similar delivery infrastructure. Morphisec said the newer downloader added stronger defense-evasion behavior and later delivered Remcos RAT and Eternity Stealer.
Morphisec said the NFT-001 malware campaign has targeted users in crypto and NFT communities since November 2020, primarily through phishing messages on Discord and similar forums that led victims to fake crypto-themed sites.
The fake Pixelmon site served ZIP archives including setup.zip, whose LNK file launched PowerShell to download system32.hta and install Vidar infostealer. Researchers found the malware used Telegram to obtain command-and-control information and then downloaded additional modules to steal passwords, wallet data, and other sensitive files.
Threat actors set up a fake Pixelmon website at pixelmon[.]pw impersonating the legitimate pixelmon.club project to lure users with free tokens and collectibles into downloading malware. MalwareHunterTeam was credited with first discovering the malicious site.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 48 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.